CloudBees, the enterprise DevOps leader powering the continuous economy, along with survey lead Sonatype, announced the results of the 6th annual DevSecOps Community Survey today. While DevOps practices are maturing rapidly, corporate application security initiatives are only gradually gaining traction, according to a survey released today by Sonatype, CloudBees, Carnegie Mellon's Software Engineering Institute and several other partners. The 2019 DevSecOps Community Survey of 5,558 IT professionals also found that organizations with elite DevSecOps programs are outperforming others in terms of DevOps automation, open source controls, container controls, training and cybersecurity preparedness. The 6th annual DevSecOps Community Survey was led by Sonatype with CloudBees as a major sponsor.

The survey showed that 28 percent of all organizations have adopted "very mature" DevOps practices, company-wide or in pockets, up slightly from 25 percent in 2018. Another 49 percent reported their DevOps practices as "improving." Overall, 95 percent of respondents say their organizations are using advanced development processes - agile, DevOps and/or continuous integration/continuous delivery (CI/CD) - with the remainder clinging to legacy waterfall development methods. Deployments are also getting more frequent - with 9 percent saying they deploy with every change and 65 percent deploying at least once per week.

"The clear increase in adoption of modern development practices of Agile, CD and DevOps signifies important progress in the software delivery space," said Brian Dawson, DevOps evangelist, CloudBees. "These practices are the foundation for the wider adoption of DevSecOps practices and a security-first mindset. Software is intertwined in the very fabric of our business and personal lives, making it critical that we continuously secure software by automating key security practices into the development and delivery pipeline. There's still a lot of work to do to get to DevSecOps but, as an industry, we are making progress."

The survey showed mixed levels of progress on the security front. Overall, only 54 percent of respondents said their organizations have cybersecurity incident response plans in place - the same as 2018. More than a quarter (26 percent) have no protections for confidential information like passwords and API keys. And security tools are still not well integrated with the DevOps pipeline: 11 percent are fully integrated and automated, while 75 percent are not or are only partially integrated.

Breaches are still happening, but they're becoming less frequent. Seventeen percent of respondents said their companies experienced a breach definitely or possibly tied to a web application vulnerability in the past year - down from one third a year ago.

Developers themselves seem to want to get more involved in the application security (appsec) process. Based on the survey, 28 percent were fully focused on appsec, and another 46 percent want to be but are too busy. To get up to speed they'd need training - but 17 percent of survey takers said their companies have no appsec training available.

Meanwhile, organizations that have developed "elite" practices are outperforming peers in several areas. For example, in DevOps automation, elite DevSecOps practices are six times more likely to have fully integrated and automated security practices across the DevOps pipeline than their less mature peers. In open source controls, 62 percent with elite programs have an open source governance policy in place, and follow it, compared to just a quarter of those without DevOps practices. For container controls, 51 percent of respondents with elite practices say they leverage security products to identify vulnerabilities in containers, while only 16 percent of those without said the same thing.

Cloud-Native thinking and Serverless Computing are now the norm in financial services, manufacturing, telco, healthcare, transportation, energy, media, entertainment, retail and other consumer industries, as well as the public sector.

The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential.

DevOpsSUMMIT at CloudEXPO expands the DevOps community, enable a wide sharing of knowledge, and educate delegates and technology providers alike. Recent research has shown that DevOps dramatically reduces development time, the amount of enterprise IT professionals put out fires, and support time generally. Time spent on infrastructure development is significantly increased, and DevOps practitioners report more software releases and higher quality. Sponsors of DevOpsSUMMIT at CloudEXPO will benefit from unmatched branding, profile building and lead generation opportunities.

At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throughout enterprises of all sizes.

ServerlessSUMMIT at CloudEXPO to Present 50 Rockstar Speakers and 60 Serverless and Kubernetes Sessions in Three Simultaneous Tracks

This month @nodexl announced that ServerlessSUMMIT & DevOpsSUMMIT own the world's top three most influential Kubernetes domains which are more influential than LinkedIn, Twitter, YouTube, Medium, Infoworld and Microsoft combined.

The three-day event will take place June 24-26, 2019 at the Santa Clara Convention Center, Santa Clara, CA and will be colocated with CloudEXPO Silicon Valley!

Today we have announced our first 12 sessions. We are accepting speaking submissions for ServerlessSUMMIT through Friday, February 8th.

Our CloudEXPO Silicon Valley 2019 schedule showcases 200 presentations, including keynotes, technical sessions, general sessions, power panels, and hands-on tutorials presented by 150 rockstar speakers in the 10 hottest conference tracks of 2019. We are excited to add the ServerlessSUMMIT to this lineup!

Cloud-Native thinking and Serverless Computing are now the norm in financial services, manufacturing, telco, healthcare, transportation, energy, media, entertainment, retail and other consumer industries, as well as the public sector.

The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential.

As they do so, IT professionals are also embracing the reality of Serverless architectures, which are critical to developing and operating real-time applications and services. Serverless is particularly important as enterprises of all sizes develop and deploy Internet of Things (IoT) initiatives.

Serverless and Kubernetes are great examples of continuous, rapid pace of change in enterprise IT. They also raise a number of critical issues and questions about employee training, development processes, and operational metrics.

The Most Popular 20 Cloud-Native, Serverless and Kubernetes Speakers and Sessions at ServerlessSUMMIT Silicon Valley

ServerlessSUMMIT and DevOpsSUMMIT at CloudEXPO expands the DevOps community, enable a wide sharing of knowledge, and educate delegates and technology providers alike.

There's a real need for serious conversations about Serverless and Kubernetes among the people who are doing this work and managing it.

So we are very pleased today to announce the ServerlessSUMMIT at CloudEXPO.

At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throughout enterprises of all sizes.

CloudEXPO Has Been the M&A Capital For Cloud Companies For More Than a Decade

CloudEXPO has been the M&A capital for Cloud companies for more than a decade with memorable acquisition news stories which came out of CloudEXPO expo floor. DevOpsSUMMIT New York faculty member Greg Bledsoe shared his views on IBM's Red Hat acquisition live from NASDAQ floor. Acquisition news was announced during CloudEXPO New York which took place November 12-13, 2019 in New York City.

CloudEXPO is the single event where technology buyers and vendors meet to experience and discus cloud computing and all that it entails. For more than a decade, sponsors and exhibitors of CloudEXPO benefit from unmatched branding, profile building and lead generation opportunities through our following unique tools. For more information on sponsorship, exhibit, and keynote opportunities call us at 954 242-0444 or contact us ▸ Here

Featured on-site presentation and ongoing on-demand webcast exposure to a captive audience of industry decision-makers

Showcase exhibition during our new extended dedicated expo hours

Breakout Session Priority scheduling for Sponsors that have been guaranteed a 40-minute technical session

Online advertising on 4,5 million article pages in SYS-CON's leading i-Technology Publications

Capitalize on our Comprehensive Marketing efforts leading up to the show with print mailings, e-newsletters and extensive online media coverage

Press releases sent on major wire services to over 500 industry analysts

About DXWorldEXPO LLC

DXWorldEXPO LLC is a Lighthouse Point, Florida-based trade show company and the creator of DXWorldEXPO - Digital Transformation Conference & Expo. The company produces and presents the world's most influential technology events including CloudEXPO, DevOpsSUMMIT, and FinTechEXPO.

Your applications have evolved, your computing needs are changing, and your servers have become more and more dense. But your data center hasn't changed so you can't get the benefits of cheaper, better, smaller, faster... until now. Colovore is Silicon Valley's premier provider of high-density colocation solutions that are a perfect fit for companies operating modern, high-performance hardware. No other Bay Area colo provider can match our density, operating efficiency, and ease of scalability.

Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches.
In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, discussed why containers should be paired with new architectural practices such as microservices rather than mimicking legacy server virtualization workflows and architectures.

Your applications have evolved, your computing needs are changing, and your servers have become more and more dense. But your data center hasn't changed so you can't get the benefits of cheaper, better, smaller, faster... until now. Colovore is Silicon Valley's premier provider of high-density colocation solutions that are a perfect fit for companies operating modern, high-performance hardware. No other Bay Area colo provider can match our density, operating efficiency, and ease of scalability.

At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throughout enterprises of all sizes.

Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches.
In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, discussed why containers should be paired with new architectural practices such as microservices rather than mimicking legacy server virtualization workflows and architectures.

At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throughout enterprises of all sizes.

Skeuomorphism usually means retaining existing design cues in something new that doesn’t actually need them. However, the concept of skeuomorphism can be thought of as relating more broadly to applying existing patterns to new technologies that, in fact, cry out for new approaches.
In his session at DevOps Summit, Gordon Haff, Senior Cloud Strategy Marketing and Evangelism Manager at Red Hat, discussed why containers should be paired with new architectural practices such as microservices rather than mimicking legacy server virtualization workflows and architectures.

Take advantage of autoscaling, and high availability for Kubernetes with no worry about infrastructure. Be the Rockstar and avoid all the hurdles of deploying Kubernetes. So Why not take Heat and automate the setup of your Kubernetes cluster? Why not give project owners a Heat Stack to deploy Kubernetes whenever they want to?
Hoping to share how anyone can use Heat to deploy Kubernetes on OpenStack and customize to their liking.
This is a tried and true method that I've used on my OpenStack clusters and I will share the benefits, bumps along the way and the lessons learned.

This week I had the pleasure of delivering the opening keynote at Cloud Expo New York. It was amazing to be back in the great city of New York with thousands of cloud enthusiasts eager to learn about the next step on their journey to embracing a cloud-first worldl."

@SteveMar_Msft

“

How does Cloud Expo do it every year? Another INCREDIBLE show - our heads are spinning - so fun and informative."

@SOASoftwareInc

“

Thank you @ThingsExpo for such a great event. All of the people we met over the past three days makes us confident IoT has a bright future."

@Cnnct2me

“

One of the best conferences we have attended in a while. Great job, Cloud Expo team! Keep it going."

Business Executives including CEOs, CMOs, & CIOs ,
Presidents & SVPs,
Directors of Business Development ,
Directors of IT Operations,
Product and Purchasing Managers,
IT Managers.

Join Us as a Media Partner - Together We Can Enable the Digital Transformation!

SYS-CON Media has a flourishing Media Partner program in which mutually beneficial promotion and benefits are arranged between our own leading Enterprise IT portals and events and those of our partners.

If you would like to participate, please provide us with details of your website/s and event/s or your organization and please include basic audience demographics as well as relevant metrics such as ave. page views per month.